漏洞描述 【漏洞对象】Drupal 【涉及版本】 7.58之前的Drupal,8.3.9之前的8.x,8.4.6之前的8.4.x和8.5.1之前的8.5.x 【漏洞描述】7.58之前的Drupal,8.3.9之前的8.x,8.4.6之前的8.4.x和8.5.1之前的8.5.x允许远程攻击者执行任意代码,因为这样会影响具有默认或通用模块配置的多个子系统。
相关漏洞推荐 CVE-2019-6340: Drupal 8 core RESTful Web Services RCE POC CVE-2014-3704: Drupal SQL Injection POC CVE-2018-7600: Drupal - Remote Code Execution POC CVE-2018-7602: Drupal - Remote Code Execution POC CVE-2018-9205: Drupal avatar_uploader v7.x-1.0-beta8 - Local File Inclusion POC CVE-2019-6340: Drupal - Remote Code Execution POC CVE-2024-45440: Drupal 11.x-dev - Full Path Disclosure POC CVE-2014-3704: Drupal SQL Injection POC CVE-2018-7600: Drupal Drupalgeddon 2 RCE POC drupal-jsonapi-user-listing: Drupal JSON:API Username Listing - Detect POC drupal-install: Drupal Install POC drupal-avatar-xss: Drupal Avatar Uploader - Cross-Site Scripting POC drupal7-elfinder-rce: Drupal 7 Elfinder - Remote Code Execution